GDPR Compliance
SpiderOak's Compliance with GDPR
The General Data Protection Regulation (GDPR) is a European Union (EU) regulation providing data protection for people in the EU, replacing the 1995 Data Protection Directive. In essence it requires businesses that hold data to adhere to standards that SpiderOak has always maintained. In fact, we built our No Knowledge privacy environment specifically to handle the task of safeguarding our customers' data and privacy. The SpiderOak applications SpiderOakONE and SpiderOak Groups comply with the GDPR.
Although the GDPR only applies to people in the EU, we believe everyone deserves data protection. All of our customers, regardless of citizenship or location, enjoy the same high standards of privacy and security.
SpiderOak's servers are located in the United States, so it is relevant to note that under the GDPR the transfer of personal data to a country outside the EU is allowed if the company provides appropriate legal safeguards, which SpiderOak always has. In our opinion this focus on contracts and codes of conduct misses the point, however. While legal restrictions are good, history shows that you should not blindly trust your vendor nor public authorities. For that reason, SpiderOakONE encrypts your files before they leave your computer using encryption keys that only you hold. You don't have to trust us (or nosy third parties, or overreaching authorities) to obey the law, because no one but you is able to decrypt your data. That is the essence of our No Knowledge privacy environment.
For information on our datacenter certifications, see Datacenter Certifications.
What User Data Does SpiderOak Have?
As a company, we keep very sparing information about our users. We don't hoard personally identifiable information (PII), and we never sell your information or share it with advertisers. The information you provide to us directly is:
Your name. If you provide this information to us, we have it. We take it at your word that the name you provide is your real name, but we have no way of verifying this. You can use an alias if you prefer.
Your email address. If you provide your actual email address during account setup, it's in our records.
Billing information. If you set up a subscription with us, our payment processor has that information. We might be able to see the last four digits of your card number, and possibly the country of origin for your card, but not always.
We also receive some limited information automatically when you use our products, such as your Internet Protocol (IP) address, basic device and software data, and system-generated error messages. Our Privacy Policy carries the complete inventory of the information we collect and the third-party services that help us provide our products.
We silo all information. IP addresses are not stored together with other PII such as email addresses or names, so you don't have to worry about there being spreadsheets or databases somewhere listing your name alongside your email address, IP address, or other PII.
We have information about our users in three main places:
Stripe, our payment processor. If you have an active subscription with us, Stripe processes those payments. The information found here is usually only going to be your email address and your card information, and perhaps your name. The card information isn't visible to us, and is encrypted by Stripe. We don't collect anything other than the billing information for your subscriptions. We can remove your information from our Stripe records upon request.
Our marketing lists. Typically, these lists only contain your email address. We can remove you from our marketing mailing lists upon request.
Our servers. Server records will contain the name and email address you provided at account creation, along with your billing history if you have an active subscription with us. Any data you upload to us is stored as an encrypted blob of data blocks, and you are the only person with the keys to unlock it. When an account is canceled, that data is removed from our servers. Our server records cannot be removed for tax liability reasons: we have to retain billing records practically indefinitely, and there is no way to redact one part of the information from these records without removing everything. Again, we do silo information to help protect our users' PII.
Cancelling an Account and the “Right to Be Forgotten”
If you decide to cancel your account, please follow the steps outlined in Cancelling a SpiderOak One account.
Once your account is canceled, you can contact our support team to request that your personal data be deleted. Please note that this is not possible on active accounts.
Terms of Service and Privacy Policy
Further details on how SpiderOak handles personally identifiable information and user data can be found in our Terms and Conditions and our Privacy Policy, along with complete legal disclaimers. For any other inquiries regarding the GDPR or your personal data, please contact our support team.
